Severity
6.5MEDIUMNVD
EPSS
8.6%
top 7.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 13

Description

NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 2.2 | Impact: 4.2

Affected Packages6 packages

NVDntp/ntp4.3.04.3.90+2
debiandebian/ntp< ntp 1:4.2.8p7+dfsg-1 (bullseye)
NVDfreebsd/freebsd10.010.1+3
Debianntp/ntp< 1:4.2.8p7+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10+1

Also affects: Ubuntu Linux 12.04, 14.04, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-rjg7-f2g5-4qhq: NTP before 42022-05-13
OSV
CVE-2015-7973: NTP before 42017-01-30
OSV
ntp vulnerabilities2016-10-05

📋Vendor Advisories

18
CISA ICS
Siemens TIM 4R-IE Devices2021-04-13
Ubuntu
NTP vulnerabilities2016-10-05
Palo Alto
PAN-SA-2016-0019 NTP Vulnerabilities2016-08-15
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 20162016-01-28
BSD
FreeBSD-SA-16:09.ntp: Multiple vulnerabilities of ntp2016-01-27

💬Community

2
Bugzilla
CVE-2015-7973 ntp: replay attack on authenticated broadcast mode2016-01-20
Bugzilla
CVE-2015-7974 CVE-2015-8138 CVE-2015-7973 CVE-2015-7975 CVE-2015-7976 CVE-2015-7977 CVE-2015-7978 CVE-2015-7979 CVE-2015-8158 CVE-2015-8139 CVE-2015-8140 ntp: various flaws [fedora-all]2016-01-20